UpdateStar Vulnerability Index · September 2026

Monthly severity snapshot for widely-installed consumer software

82
Overall Score

SEVERE

September 2026 is the worst month of the year so far. Two China-linked espionage groups chained two Chrome V8 zero-days with a Windows kernel zero-day (ALPC) to break out of the browser sandbox and take full control of victims' PCs, and all three flaws are now on CISA KEV. Microsoft then shipped the largest Patch Tuesday in its history, roughly 964 CVEs, including two exploited zero-days and 20 potentially wormable bugs. Google fixed 230 Chrome vulnerabilities in a single release, and WinRAR's 2025 path-traversal flaw is in its 14th month of active abuse. The one piece of good news: 7-Zip has finally shipped a fix for its Mark-of-the-Web bypass.

4 × KEV Listed APT Active (China-linked) 1 × Fix Released ~964 MS CVEs · Record

Top 5 — Consumer App Severity

#1
Google Chrome CVE-2026-85046 / -87491
V8 type confusion (heap read/write) chained with a V8 out-of-bounds write that escapes the V8 sandbox · 6th and 7th Chrome zero-days of 2026 · exploited since Sep 1 by China-linked groups UTA0560 and JungleBamboo against NGOs, delivering the GRIMWEDGE backdoor and a malicious Chrome extension
CISA KEV Exploited ITW (China-linked APT) Patched 153.0.8010.36/.37
8.8
CVSS HIGH
#2
Microsoft Windows (ALPC) CVE-2026-85880
Heap buffer overflow in Advanced Local Procedure Call that lifts a low-privilege AppContainer to SYSTEM · final link of the Chrome exploit chain above, used to escape the browser sandbox · a second Windows zero-day (CVE-2026-81963, Windows Update Stack, CVSS 7.8) was also exploited and fixed this month
CISA KEV Exploited ITW (chained w/ Chrome) Patched Sep 8
7.8
CVSS HIGH
#3
WinRAR CVE-2025-8088
Path traversal → Startup folder · Exploitation by state- and financially-motivated groups remains widespread and ongoing, incl. two active Russia-aligned campaigns against Ukraine (SHADOW-EARTH-066, Earth Dahu/Gamaredon) · No auto-update, ~500M users exposed
CISA KEV APT Active Patched 7.13
8.4
CVSS HIGH
#4
Mozilla Firefox MFSA 2026-82
29 security fixes in Firefox 155, 10 rated high, including two sandbox escapes via use-after-free (DOM: Navigation, DOM: Security) and a WebGPU privilege escalation · no confirmed in-the-wild exploitation, auto-update reliable
Patched Firefox 155
High
MOZILLA IMPACT
#5
RAR5 alternate-data-stream name collision erases the Mark-of-the-Web on extraction, defeating SmartScreen warnings · after more than two months without a fix, now resolved in 7-Zip 26.03 · no auto-update, so most installs stay exposed until users update manually
Fixed 26.03 No Auto-Update
4.8
CVSS MEDIUM

CVSS Score Comparison

Chrome 8.8
Windows (ALPC) 7.8
WinRAR 8.4
Firefox High
7-Zip 4.8
MS CVE-2026-69730 (DNS Server RCE) 9.8

Key Stats — September 2026

~964
Microsoft CVEs patched in a single Patch Tuesday (all-time record)
4
Consumer zero-days exploited ITW & added to CISA KEV (2 Chrome, 2 Windows)
7
Chrome zero-days exploited in the wild so far in 2026
230
Vulnerabilities fixed in a single Chrome release (153)
−7
Days mean time-to-exploit (Mandiant M-Trends 2026)
43
Days median KEV remediation time (Verizon DBIR 2026)

Patch Lag — Days Since Disclosure vs. Update Status

WinRAR (CVE-2025-8088) 420+ d
Patched Jul 2025 · still under active nation-state exploitation 14 months later, no auto-update
7-Zip (CVE-2026-58052) ~68 d
Disclosed Jun 28 · fixed in 26.03 in early September · manual update required
Chrome (CVE-2026-85046 / -87491) ~30 d
Reported to Google Aug 4/6 · exploited from Sep 1 via the Chromium "patch gap" · fixed Sep 3 / Sep 8
Windows (ALPC) (CVE-2026-85880) ~7 d
Exploited as a zero-day from ~Sep 1; patched Sep 8 and added to CISA KEV
Firefox (MFSA 2026-82) <7 d
Fixed Sep 1 · auto-update reliable
Data sources: NVD · CISA KEV · Mandiant M-Trends 2026 · Verizon DBIR 2026 · vendor advisories (Microsoft MSRC, Google, Mozilla, RARLAB, 7-Zip/SourceForge) · Volexity
Check and update all software at updatestar.com · Download the UpdateStar Client for Windows

September 2026 Highlights

  • KEV5 CVEs on CISA Known Exploited Vulnerabilities list (4 new — Chrome ×2, Windows ×2; 1 carryover — WinRAR)
  • APTTwo China-linked groups used a Chrome → Windows zero-day chain; Russia-aligned actors continue abusing WinRAR
  • FIX7-Zip's Mark-of-the-Web bypass is finally fixed in version 26.03
  • MS~964 Microsoft CVEs in a single Patch Tuesday — the largest ever

Overall Severity Score

Index Score 82 / 100
Rating SEVERE

App Quick Reference

  • HIGH Chrome 8.8
  • HIGH WinRAR 8.4
  • HIGH Windows (ALPC) 7.8
  • HIGH Firefox High*
  • MED 7-Zip 4.8

Patch Status

  • Chrome — patched (153.0.8010.36/.37); KEV-listed, restart to apply
  • Windows — patched Sep 8 (September cumulative update); 2 KEV-listed zero-days
  • WinRAR — patched but no auto-update, still actively exploited
  • Firefox — patched (155, auto-update); no confirmed ITW
  • 7-Zip — fixed in 26.03, but no auto-update — update manually

Data Sources

  • NVD (National Vulnerability Database)
  • CISA Known Exploited Vulnerabilities
  • Mandiant M-Trends 2026
  • Verizon DBIR 2026
  • Vendor security advisories